Vulnerabilities > CVE-2006-4580 - Remote vulnerability in the Address Book the Address Book 1.04E

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
the-address-book

Summary

register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".

Vulnerable Configurations

Part Description Count
Application
The_Address_Book
1